CVE-2026-25173Patch(microsoft / windows_10_1607)

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-03-16); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline9 mentions / 5d
01345Mentions · 2026-03-15: 1Mentions · 2026-03-16: 5Mentions · 2026-03-17: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 3Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 5Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 103-1503-1603-1703-2003-23
Signal classification2 categories
Patch
777.8%
Disclosure
222.2%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-151
Patch1
2026-03-165
Disclosure2Patch3
2026-03-171
Patch1
2026-03-201
Patch1
2026-03-231
Patch1
Full discourse9 posts
  • kokumօtօ@__kokumoto
    Patch

    マイクロソフトがWindows 11向けに定例外ホットパッチ更新を配信。Windows Routing and Remote Access Service (RRAS)関連の脆弱性3件、CVE-2026-25172、CVE-2026-25173、CVE-2026-26111への対応。 https://cybersecuritynews.com/windows-11-out-of-band-update/

    Post summary

    Microsoft has issued an out‑of‑band patch for three RRAS‑related CVEs (CVE‑2026‑25172, CVE‑2026‑25173, CVE‑2026‑26111) affecting Windows 11, with the update now available.

    03031958
    7.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11 https://cybersecuritynews.com/windows-11-out-of-band-update/ 『(直訳) 対処対象となる3つのCVEは以下のとおりです。 CVE-2026-25172 — RRAS管理ツールにおけるセキュリティ上の欠陥。悪意のあるリモートサーバーがサービス運用を妨害したり、接続されたデバイス上で任意のコードを実行したりすることが可能になる。 CVE-2026-25173 — 同様の攻撃手法を用いた関連するRRASの脆弱性。被害者が攻撃者制御のサーバーに接続した際に、リモートコード実行やサービス拒否状態を引き起こす可能性がある。 CVE-2026-26111 — 上記の脆弱性のリスクを悪化させるRRASのセキュリティ上の追加問題。適切な条件下ではコード実行が可能になる可能性がある。』

    Post summary

    Microsoft has released an out‑of‑band patch targeting three critical RRAS remote code execution vulnerabilities (CVE‑2026‑25172, CVE‑2026‑25173, CVE‑2026‑26111), which allow attackers to execute arbitrary code or cause denial of service on affected Windows 11 systems.

    110111.0K
    11.4K followersView on X
  • bigmacd@bigmacd16684
    Patch

    Microsoft re-released hotpatch KB5084597 for Windows 11 24H2/25H2 & Enterprise LTSC 2024 to fix 3 RRAS RCE flaws (CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111) allowing a domain-authenticated attacker

    Post summary

    Microsoft released hotpatch KB5084597 for Windows 11 24H2/25H2 and Enterprise LTSC 2024 to remediate three RRAS remote code‑execution vulnerabilities (CVE‑2026‑25172, CVE‑2026‑25173, and CVE‑2026‑26111). No PoC, exploit code, or evidence of active exploitation is mentioned.

    1000088
    3 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Windows RRAS の脆弱性 CVE-2026-25172/25173/26111 が FIX:緊急のホットパッチ提供 https://iototsecnews.jp/2026/03/15/microsoft-releases-out-of-band-patch-for-critical-rras-rce-vulnerabilities-in-windows-11/ Microsoft が、Windows 11 24H2/25H2 を対象とした、緊急の定例外ホットパッチ KB5084597 をリリースしました。今回の修正は、Windows の Routing and Remote Access Service (RRAS) 管理ツールに存在するメモリ管理の不備が原因となる、3 件のリモートコード実行 (RCE) 脆弱性に対処するものです。 RRAS は、企業ネットワークにおいて VPN 接続やルーティングを管理するための重要なコンポーネントです。修正された CVE-2026-25172/CVE-2026-25173/CVE-2026-26111 は、管理者が RRAS ツールを使用して外部サーバに接続する際に発動するものです。 攻撃者が悪意を持って構築した 偽の RRAS サーバに対して、管理者が接続を試みると、サーバからの不正な応答により、管理者のマシン上で任意のコード実行やサービス拒否 (DoS) が発生するというリスクがあります。ご利用のチームは、ご注意ください。 #CVE202625172 #CVE202625173 #CVE202626111 #Microsoft #RRAS #Vulnerability #Windows

    Post summary

    Microsoft issued an urgent hot patch KB5084597 to fix three critical RCE vulnerabilities in the Windows 11 RRAS routing service, urging administrators to apply the update promptly.

    01000186
    484 followersView on X
  • Haseeb Efani@Haseeb_Efani
    Patch

    BleepingComputer says the hotpatch is cumulative and follows March fixes for CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111.

    Post summary

    BleepingComputer reports a cumulative hotpatch that applies the March fixes for CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111, providing remediation coverage.

    1000044
    2 followersView on X
  • 【學】@manabu2111
    Patch

    Microsoftが「KB5084597」を定例外でリリース ~「Hotpatch」でリモートコード実行 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2093553.html 、本パッチは、Windowsのリモート アクセス サービス(RRAS)管理ツールで発見されたリモートコードの脆弱性(CVE-2026-25172、CVE-2026-25173、CVE-2026-26111)に、(続く)

    Post summary

    Microsoft issued hotpatch KB5084597 to fix remote code execution vulnerabilities (CVE-2026-25172, CVE-2026-25173, CVE-2026-26111) found in the Windows Remote Access Service management tool.

    1000093
    2.2K followersView on X
  • Cert-IST@cert_ist
    Patch

    Microsoft publie un hotpatch OOB pour corriger des failles RCE (CVE-2026-25172, CVE-2026-26111, CVE-2026-25173) dans RRAS sur Windows 11 Enterprise. https://tinyurl.com/2bsyh2e9

    Post summary

    Microsoft has released an out‑of‑band hotpatch to address three RCE vulnerabilities in the RRAS component of Windows 11 Enterprise.

    0000098
    963 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25173 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-25173 ----- Traducción: CVE-2026-25173 Desbordamiento de entero o … http://infoflow.cloud`

    Post summary

    The post briefly discloses CVE-2026-25173, noting an integer overflow in Windows RRAS that enables code execution by authorized attackers, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000050
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25173 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-25173

    Post summary

    The text announces CVE‑2026‑25173, noting an integer overflow in Windows RRAS that could lead to remote code execution, but provides no evidence of active exploitation, PoC, or mitigation steps.

    00000452
    56.7K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more